Openmeetings
Vendor:
First CVE: Apr 11, 2016 · Active for 10 years
29
Total CVEs
More Total CVEs than 96% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openmeetings over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2016
10 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Openmeetings29 CVEs
31%
52%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network29 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (96.6%)
High1 (3.4%)
Unknown0 (0.0%)
User Interaction
None25 (86.2%)
Unknown0 (0.0%)
Required4 (13.8%)
Privileges Required
Low5 (17.2%)
High1 (3.4%)
None23 (79.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13951HIGH Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | Sep 30, 2020 | 7.5 | 72 | NO | YES |
CVE-2024-54676CRITICAL Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions at https://openmeetings.apache | Jan 8, 2025 | 9.8 | 67 | NO | NO |
CVE-2016-0784MEDIUM Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbit | Apr 11, 2016 | 6.5 | 56 | NO | YES |
CVE-2026-49488MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings.
This issue affects Apache OpenMeetings: from 5.0.0 before 9.1. | Jul 14, 2026 | 6.5 | 33 | NO | NO |
CVE-2017-7664CRITICAL Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. | Jul 17, 2017 | 10.0 | 33 | NO | NO |
CVE-2017-7673CRITICAL Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection. | Jul 17, 2017 | 9.8 | 31 | NO | NO |
CVE-2023-28326CRITICAL Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0
Description: Attacker can elevate their privileges in any room
| Mar 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2016-2164HIGH The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checkin | Apr 11, 2016 | 7.5 | 28 | NO | NO |
CVE-2016-0783HIGH The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user pass | Apr 11, 2016 | 7.5 | 28 | NO | NO |
CVE-2017-7681HIGH Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries bein | Jul 17, 2017 | 8.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (29 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
6.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (29 CVEs).
Media Mentions
Signals from CVEs in this product scope (29 CVEs).
Top CNAs Publishing CVEs For Openmeetings
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.1 | 11 | 7.9 | 2.1% | 0 | 0 |
| 3.2.0 | 11 | 7.9 | 2.1% | 0 | 0 |
| 3.1.5 | 9 | 8.1 | 2.1% | 0 | 0 |
| 3.1.4 | 9 | 8.1 | 2.1% | 0 | 0 |
| 3.1.3 | 9 | 8.1 | 2.1% | 0 | 0 |
| 3.1.2 | 9 | 8.1 | 2.1% | 0 | 0 |
| 3.1.1 | 9 | 8.1 | 2.1% | 0 | 0 |
| 3.1.0 | 9 | 8.1 | 2.1% | 0 | 0 |
| 3.0.7 | 8 | 7.8 | 2.0% | 0 | 0 |
| 3.0.6 | 8 | 7.8 | 2.0% | 0 | 0 |
| 3.0.5 | 8 | 7.8 | 2.0% | 0 | 0 |
| 3.0.4 | 8 | 7.8 | 2.0% | 0 | 0 |
| 3.0.3 | 8 | 7.8 | 2.0% | 0 | 0 |
| 3.0.2 | 8 | 7.8 | 2.0% | 0 | 0 |
| 3.0.1 | 8 | 7.8 | 2.0% | 0 | 0 |
| 3.0.0 | 8 | 7.8 | 2.0% | 0 | 0 |
| 2.2.0 | 8 | 7.8 | 2.0% | 0 | 0 |
| 2.1.1 | 8 | 7.8 | 2.0% | 0 | 0 |
| 2.1 | 8 | 7.8 | 2.0% | 0 | 0 |
| 2.0 | 8 | 7.8 | 2.0% | 0 | 0 |